Hacking News

Hacking incidents, ethical hacking, and cybercrime updates.

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Hacking News
1 min read

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager

CyberShield TeamRead More
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Hacking News
1 min read

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahe

CyberShield TeamRead More
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Hacking News
1 min read

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under a

CyberShield TeamRead More
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Hacking News
1 min read

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Lati

CyberShield TeamRead More
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Hacking News
1 min read

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which th

CyberShield TeamRead More
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
Hacking News
1 min read

Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing reco

CyberShield TeamRead More
How Synthetic Identity Fraud is Coming for Machine Identities
Hacking News
1 min read

How Synthetic Identity Fraud is Coming for Machine Identities

Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real

CyberShield TeamRead More
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
Hacking News
1 min read

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

RefluXFS, a Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualy

CyberShield TeamRead More
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Hacking News
1 min read

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organizat

CyberShield TeamRead More
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Hacking News
1 min read

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Othe

CyberShield TeamRead More
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Hacking News
1 min read

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a sil

CyberShield TeamRead More
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Hacking News
1 min read

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent i

CyberShield TeamRead More
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Hacking News
1 min read

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS sco

CyberShield TeamRead More
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Hacking News
1 min read

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what

CyberShield TeamRead More
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
Hacking News
1 min read

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugg

CyberShield TeamRead More
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
Hacking News
1 min read

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authori

CyberShield TeamRead More
The Fastest Path to AI Adoption Runs Through Security
Hacking News
1 min read

The Fastest Path to AI Adoption Runs Through Security

Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, empl

CyberShield TeamRead More
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Hacking News
1 min read

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live ga

CyberShield TeamRead More
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Hacking News
1 min read

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete c

CyberShield TeamRead More
Why Modern SOCs Need Multi-Layered Detections
Hacking News
1 min read

Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defen

CyberShield TeamRead More
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Hacking News
1 min read

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media rep

CyberShield TeamRead More
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Hacking News
1 min read

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop

CyberShield TeamRead More
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Hacking News
1 min read

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522

CyberShield TeamRead More
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Hacking News
1 min read

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vul

CyberShield TeamRead More
N-day is Becoming N-Hour. Patching Faster Won't Save You.
Hacking News
1 min read

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into

CyberShield TeamRead More
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
Hacking News
1 min read

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim beh

CyberShield TeamRead More
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
Hacking News
1 min read

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same a

CyberShield TeamRead More
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Hacking News
1 min read

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic

CyberShield TeamRead More
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Hacking News
1 min read

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable website

CyberShield TeamRead More
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Hacking News
1 min read

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine secu

CyberShield TeamRead More
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Hacking News
1 min read

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed syst

CyberShield TeamRead More
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Hacking News
1 min read

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder

CyberShield TeamRead More
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Hacking News
1 min read

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to

CyberShield TeamRead More
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Hacking News
1 min read

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar e

CyberShield TeamRead More
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
Hacking News
1 min read

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI

CyberShield TeamRead More
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Hacking News
1 min read

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend

CyberShield TeamRead More
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Hacking News
1 min read

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipmen

CyberShield TeamRead More
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
Hacking News
1 min read

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The fi

CyberShield TeamRead More
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Hacking News
1 min read

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of s

CyberShield TeamRead More
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
Hacking News
1 min read

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected

CyberShield TeamRead More
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
Hacking News
1 min read

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched

CyberShield TeamRead More
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
Hacking News
1 min read

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public dis

CyberShield TeamRead More
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Hacking News
1 min read

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to

CyberShield TeamRead More
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
Hacking News
1 min read

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced One

CyberShield TeamRead More
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Hacking News
1 min read

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yu

CyberShield TeamRead More
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
Hacking News
1 min read

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that

CyberShield TeamRead More
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
Hacking News
1 min read

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job

CyberShield TeamRead More
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Hacking News
1 min read

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described

CyberShield TeamRead More
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
Hacking News
1 min read

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with Comf

CyberShield TeamRead More
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Hacking News
1 min read

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story bel

CyberShield TeamRead More
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Hacking News
1 min read

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts.

CyberShield TeamRead More
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Hacking News
1 min read

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campa

CyberShield TeamRead More
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
Hacking News
1 min read

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acqu

CyberShield TeamRead More
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Hacking News
1 min read

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The aff

CyberShield TeamRead More
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
Hacking News
1 min read

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to exe

CyberShield TeamRead More
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Hacking News
1 min read

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointe

CyberShield TeamRead More
New Webinar: Closing the Approval Gap in AI-Era Ad Tech
Hacking News
1 min read

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reve

CyberShield TeamRead More
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
Hacking News
1 min read

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC,

CyberShield TeamRead More
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Hacking News
1 min read

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive

CyberShield TeamRead More
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
Hacking News
1 min read

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live ac

CyberShield TeamRead More
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
Hacking News
1 min read

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance fro

CyberShield TeamRead More
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Hacking News
1 min read

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command ex

CyberShield TeamRead More
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Hacking News
1 min read

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the moder

CyberShield TeamRead More
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
Hacking News
1 min read

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publi

CyberShield TeamRead More
How Pentera Turns AI Security Workflows into Validation Engines
Hacking News
1 min read

How Pentera Turns AI Security Workflows into Validation Engines

AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragment

CyberShield TeamRead More
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Hacking News
1 min read

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "Labub

CyberShield TeamRead More
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Hacking News
1 min read

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Upda

CyberShield TeamRead More
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Hacking News
1 min read

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate

CyberShield TeamRead More
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Hacking News
1 min read

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enter

CyberShield TeamRead More
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Hacking News
1 min read

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and

CyberShield TeamRead More
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Hacking News
1 min read

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in quest

CyberShield TeamRead More
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Hacking News
1 min read

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way

CyberShield TeamRead More
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Hacking News
1 min read

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook th

CyberShield TeamRead More
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Hacking News
1 min read

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been desc

CyberShield TeamRead More
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Hacking News
1 min read

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat a

CyberShield TeamRead More
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
Hacking News
1 min read

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming mo

CyberShield TeamRead More
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
Hacking News
1 min read

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report,

CyberShield TeamRead More
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Hacking News
1 min read

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and

CyberShield TeamRead More
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
Hacking News
1 min read

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker

CyberShield TeamRead More
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
Hacking News
1 min read

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the thr

CyberShield TeamRead More
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
Hacking News
1 min read

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege es

CyberShield TeamRead More
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Hacking News
1 min read

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside da

CyberShield TeamRead More
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Hacking News
1 min read

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic

CyberShield TeamRead More
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
Hacking News
1 min read

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO resear

CyberShield TeamRead More
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Hacking News
1 min read

URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external secu

CyberShield TeamRead More
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
Hacking News
1 min read

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the ne

CyberShield TeamRead More
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Hacking News
1 min read

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operato

CyberShield TeamRead More
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Hacking News
1 min read

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprisi

CyberShield TeamRead More
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Hacking News
1 min read

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one har

CyberShield TeamRead More
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Hacking News
1 min read

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According

CyberShield TeamRead More
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
Hacking News
1 min read

Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images

Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it's enabled by default. "You can also @-ment

CyberShield TeamRead More
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Hacking News
1 min read

Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS sc

CyberShield TeamRead More
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Hacking News
1 min read

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands

CyberShield TeamRead More
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
Hacking News
1 min read

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authenticatio

CyberShield TeamRead More
Summer of Clearinghouses
Hacking News
1 min read

Summer of Clearinghouses

Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we annou

CyberShield TeamRead More
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
Hacking News
1 min read

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of

CyberShield TeamRead More
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Hacking News
1 min read

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by t

CyberShield TeamRead More
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Hacking News
1 min read

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The age

CyberShield TeamRead More
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
Hacking News
1 min read

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a s

CyberShield TeamRead More
New Ghost Phishing Wave Is Breaking Traditional Email Security
Hacking News
1 min read

New Ghost Phishing Wave Is Breaking Traditional Email Security

A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypt

CyberShield TeamRead More
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
Hacking News
1 min read

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its

CyberShield TeamRead More
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
Hacking News
1 min read

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Sec

CyberShield TeamRead More
The Verification Step Is the New ATO Battleground in 2026
Hacking News
1 min read

The Verification Step Is the New ATO Battleground in 2026

For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, s

CyberShield TeamRead More
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Hacking News
1 min read

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and ar

CyberShield TeamRead More